More jobs:
SOC Engineer
Job in
Durham, Durham County, North Carolina, 27703, USA
Listed on 2026-01-15
Listing for:
Qtsolv
Full Time
position Listed on 2026-01-15
Job specializations:
-
Engineering
Cybersecurity -
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Own 24×7 SOC operations with deep expertise in log analysis and forensics. Lead detection engineering, incident handling, evidence management, and continuous improvement across people, process, and tooling.
Key Responsibilities- Direct SOC operations: shift hygiene, SLA tracking, stakeholder comms, executive updates.
- Detection engineering and content tuning (KQL/Elastic
QL/Sigma/SPL) for EDR, identity, email, and cloud. - Lead high-severity incidents: scoping, containment, eradication, recovery, PIRs with actionable actions.
- Forensics & Evidence: acquisition (disk/mem/logs), chain-of-custody, timeline/triage, data integrity (hashing).
- Purple teaming, tabletop exercises, attack simulations; ATT&CK mapping and coverage metrics.
- Hiring, mentoring, and career development for analysts; run training and certifications plan.
- Hands‑on with SIEM (Elastic/Splunk/Chronicle) and EDR/XDR (Sentinel One/Crowd Strike), email security, and cloud telemetry.
- Proficient in log analysis, correlation, and anomaly detection; comfortable with PCAP and memory triage tools.
- Strong knowledge of IR frameworks (NIST/ISO), evidence handling, and reporting to exec/board audiences.
- Excellent verbal and written communication under pressure.
- Experience in regulated environments (fintech/edtech); knowledge of ISO 27001/27701, DPDP, RBI directions.
- SOAR design/maintenance; malware analysis fundamentals.
- MTTD/MTTR, detection coverage & false-positive rate, PIR action closure, readiness drill scores, stakeholder satisfaction.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×